A Management Review Agenda That Produces Real Decisions
The management review is where leadership is meant to steer the ISMS. Too often it becomes a status meeting that decides nothing. A sharper agenda fixes that.
By Kellwick Team · August 3, 2026 · 5 min read
The management review is one of the few places ISO 27001 explicitly asks leadership to engage with security. It is meant to be where the people who control budget and priorities look at how the ISMS is performing and decide what changes. In most companies it degrades into a slide deck nobody acts on. The fix is not more meeting. It is a better agenda.
What the Management Review Is Supposed to Do
The standard requires top management to review the ISMS at planned intervals to confirm it remains suitable, adequate, and effective. Those three words carry weight. Suitable means it still fits the business you are today, not the one you were last year. Adequate means it is enough for the risks you actually face. Effective means it is working, not just documented.
The review has two halves. It consumes a defined set of inputs, the evidence of how the ISMS has performed. And it produces outputs, meaning decisions and actions. An auditor will look for both. A review that consumes inputs but produces no decisions has failed at its actual purpose, even if it ticks the attendance box.
This is the point most teams miss. The management review is not a reporting ritual. It is a decision-making forum that happens to require good reporting as its input.
The Inputs You Have to Cover
ISO 27001 is specific about what the review must consider. Skipping inputs is a common source of audit findings, so treat this as a checklist, not a suggestion. Your review should take in:
- Status of actions from previous reviews. Did last time's decisions actually happen? This is where accountability lives.
- Changes in internal and external issues relevant to the ISMS. New products, new markets, new regulation, new threats.
- Feedback on security performance, including monitoring and measurement results and status against your objectives.
- Nonconformities and corrective actions, including what internal audits and any external audits found.
- Audit results, internal and external.
- Fulfilment of information security objectives. Are you hitting the targets you set, or drifting?
- Feedback from interested parties, such as customers, regulators, and partners.
- Results of risk assessment and status of the risk treatment plan.
- Opportunities for continual improvement.
You do not need a hundred slides for this. You need each input represented honestly, including the uncomfortable ones. A review that only shows green is not credible, and assessors know it.
Why Most Reviews Decide Nothing
If the inputs are covered but decisions do not follow, the problem is usually one of these:
- Wrong people in the room. If the attendees cannot allocate budget or reassign people, the meeting can only note issues, not resolve them. The clue is in the phrase top management. The review needs people who can actually decide.
- Information without a decision attached. A slide that says "42 open vulnerabilities" is a status update. A slide that says "42 open vulnerabilities, of which 6 are critical and unresolved past SLA because we lack coverage, and here is the proposed fix" forces a decision.
- No follow-through mechanism. Decisions are made and then evaporate because nobody owns them or tracks them to done. Next review, the same issues reappear.
- Too frequent or too rare. Monthly reviews become status meetings with nothing new to decide. Annual-only reviews are too coarse to steer anything. Most 50 to 250 person companies land on quarterly or twice yearly.
The pattern behind all of these is the same. The review is being run as communication rather than governance.
An Agenda Built to Force Decisions
Restructure the meeting so every item ends in a decision or a conscious choice to accept the status quo. A workable shape:
- Actions from last review. Go item by item. Done, not done, or changed. Not-done items get a decision now, not a deferral by default.
- Risk and treatment status. What has changed in the risk picture? Which treatments are behind, and do we accept the exposure or fund the fix?
- Performance against objectives. Where are we off target, and what decision closes the gap?
- Audit and nonconformity review. What did internal and external audits surface? Are corrective actions on track, and if not, what changes?
- Changes and emerging issues. New products, regulations, vendors, or threats that alter our risk. What do we adjust?
- Resourcing decision. Given everything above, is the ISMS adequately resourced? This is often the most important decision and the one most often skipped.
- Decisions and owners. Every output captured with an owner and a date, to be checked at the next review.
The discipline is the last column of every item: what was decided and who owns it. If an item generates no decision, say so explicitly and record that you consciously chose to accept the current state. That is itself a valid, auditable output.
Making the Decisions Stick
A great meeting with no follow-through is just a well-run status update. The value is realised between reviews, in whether decisions get executed. A few habits make that happen:
- Record decisions in a single tracked list with owner and due date, not buried in meeting minutes.
- Give someone responsibility for chasing actions between reviews, so they do not only surface at the next meeting.
- Open every review with the previous review's actions, and make not-done a genuinely uncomfortable place to be.
- Keep the minutes as real evidence. An assessor will want to see that the review happened, covered the required inputs, and produced decisions that were acted on. Thin minutes suggest a thin review.
Handled this way, the management review becomes the one meeting where security actually gets steered by the people who can steer it. That is worth far more than the compliance credit it earns.
Bottom Line
An ISO 27001 management review earns its place only when it covers the required inputs honestly, puts decision-makers in the room, and ends every item with a decision and an owner. The measure of a good review is not how much was reported but how much was decided and then done. If your reviews feel like status meetings that change nothing, the agenda, not the effort, is usually the problem.
If you want a second opinion on whether your management review would satisfy an auditor and actually drive your security programme, a Kellwick readiness review can look at your cadence, inputs, and follow-through and show you where it falls short.
Where this fits
ISO 27001
Pass the audit. We find what blocks Stage 1 before the certification body does.
Read the ISO 27001 hubNeed a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.